Privacy Policy

Last updated: December 2024

1. Data Controller

The controller responsible for data processing on this website is:

Domenic Wehkamp
Südeschstraße 40
48429 Rheine, Germany
Email: hello@kavyr.dev

2. Data We Collect

2.1 When Using the Kavyr CLI Tool

  • Device ID (anonymous, randomly generated identifier)
  • Scanned package names
  • Timestamp of scan requests

2.2 When Registering/Logging In

  • Email address
  • Name (if provided)
  • Payment information for Pro subscriptions (processed by Stripe)

2.3 Automatically Collected Data

  • IP address (anonymized)
  • Browser type and version
  • Operating system
  • Access timestamp

3. Purpose of Data Processing

  • Providing the security scanning service
  • Improving our threat database
  • Billing for Pro subscriptions
  • Technical operation of the website
  • Abuse prevention

4. Legal Basis

Processing is based on Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (legitimate interest in providing and improving our service), and Art. 6(1)(a) GDPR (consent, where given).

5. Data Retention

  • Scan logs: 30 days
  • Account data: Until account deletion
  • Billing data: 10 years (legal retention requirement)

6. Third-Party Providers & Data Processing

We work with the following service providers, with whom – where required – Data Processing Agreements (DPA) pursuant to Art. 28 GDPR have been concluded:

Convex (Backend Service)

We use Convex for data storage and API delivery. Provider: Convex, Inc., USA.

Stripe (Payment Processing)

For Pro subscriptions, we use Stripe for payment processing. Provider: Stripe, Inc., USA. Stripe processes payment data as an independent controller according to their own privacy policy.

Vercel (Hosting)

The website is hosted on Vercel. Provider: Vercel, Inc., USA. Server logs are temporarily stored for technical operation.

7. International Data Transfers (USA)

Some of our service providers (Convex, Stripe, Vercel) are located in the USA. The USA is considered a third country without an adequate level of data protection under the GDPR.

Legal basis for transfers:

  • EU-US Data Privacy Framework: Our US service providers are certified under the EU-US Data Privacy Framework, which ensures an adequate level of data protection (EU Commission Adequacy Decision of July 10, 2023).
  • Standard Contractual Clauses (SCC): Additionally, agreements based on EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR are in place.

More information about the EU-US Data Privacy Framework: www.dataprivacyframework.gov

8. Cookies

We only use technically necessary cookies. No tracking, analytics, or advertising cookies are used.

Cookie NamePurposeDurationType
kavyr-cookie-consentStores your cookie consent1 yearEssential
wos-sessionAuthentication / Login status (Clerk)SessionEssential

Note: You can disable cookies in your browser settings. However, this may limit the functionality of the website (e.g., login may not work).

9. Your Rights

You have the following rights regarding your personal data:

  • Access – What data we have stored about you
  • Rectification – Correction of inaccurate data
  • Erasure – Deletion of your data
  • Restriction – Limiting processing
  • Data Portability – Export of your data
  • Objection – Against certain processing activities

Contact us at hello@kavyr.dev to exercise your rights.

10. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.